Insecure library loading in Samba - CVE-2017-7494
Published: May 24, 2017 / Updated: March 30, 2023
Vulnerability identifier: #VU6676
CSH Severity: Medium
CVSS v4: 9.4 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H]
CVE-ID: CVE-2017-7494
CWE-ID: CWE-426
Exploitation vector: Adjecent network
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a remote authenticated attacker to execute arbitrary code on vulnerable server.
The vulnerability exists due to insecure library loading mechanism, when processing files on file shares. A remote attacker with ability to upload file on SMB share can upload and execute arbitrary shared library on the server with privileges of the Samba process.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
The vulnerability exists due to insecure library loading mechanism, when processing files on file shares. A remote attacker with ability to upload file on SMB share can upload and execute arbitrary shared library on the server with privileges of the Samba process.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
Affected software
Samba
Amazon Linux AMI
Gentoo Linux
Arch Linux
CentOS
Red Hat Enterprise Linux for x86_64
SUSE Linux
Ubuntu
Fedora
Opensuse
U.motion Builder
D-Link DNS-320
WD My Cloud
samba (Alpine package)
samba
Amazon Linux AMI
Gentoo Linux
Arch Linux
CentOS
Red Hat Enterprise Linux for x86_64
SUSE Linux
Ubuntu
Fedora
Opensuse
U.motion Builder
D-Link DNS-320
WD My Cloud
samba (Alpine package)
samba
How to mitigate CVE-2017-7494
The vulnerability is fixed in versions: 4.6.4, 4.5.10 and 4.4.14.
samba (Alpine package) - update to 4.2.14-r3
samba - addressed in versions 4.4.14-0.fc24, 4.5.10-0.fc25, 4.6.4-0.fc26
samba - addressed in versions 4.4.14-0.fc24, 4.5.10-0.fc25, 4.6.4-0.fc26
Links to Public Exploits and PoC-codes
- Exploit #8874 - CVE-2017-7494_SambaCry (SambaCry (CVE-2017-7494) exploit for Samba | bind shell without Metasploit) (March 1, 2023)
- Exploit #8566 - CVE-2017-7494_SambaCry (SambaCry (CVE-2017-7494) exploit for Samba | bind shell without Metasploit) (November 2, 2022)
- Exploit #8222 - exploit-CVE-2017-7494 (SambaCry exploit (CVE-2017-7494) ) (August 7, 2022)
- Exploit #7867 - exploit-CVE-2017-7494 (SambaCry exploit (CVE-2017-7494) ) (May 19, 2022)
- Exploit #5443 - BIT-EternalBlue-for-macOS_Linux (Exploit CVE-2017-7494 for Net Security course final Assignment. This would reveal the vulnerability of services that run in administrative priority on Linux.) (May 18, 2021)
- Exploit #5345 - noSAMBAnoCRY-CVE-2017-7494 (CVE-2017-7494 python exploit) (May 9, 2021)
- Exploit #2130 - SambaHunter (It is a simple script to exploit RCE for Samba (CVE-2017-7494 ).) (March 18, 2020)
- Exploit #138 - cve-2017-7494 (Proof-of-Concept exploit for CVE-2017-7494(Samba RCE from a writable share)) (March 18, 2020)
- Exploit #139 - exploit-CVE-2017-7494 (SambaCry exploit and vulnerable container (CVE-2017-7494)) (March 18, 2020)
- Exploit #140 - CVE-2017-7494 (Remote root exploit for the SAMBA CVE-2017-7494 vulnerability) (March 18, 2020)
- Exploit #141 - labs (Vulnerability Labs for security analysis) (March 18, 2020)
- Exploit #1210 - Samba - 'is_known_pipename()' Arbitrary Module Load (Metasploit) (March 18, 2020)
- Exploit #1211 - Samba 3.5.0 - Remote Code Execution (March 18, 2020)
- Exploit #1806 - Samba is_known_pipename() Arbitrary Module Load (March 18, 2020)
External References
Related Security Bulletins
- Insecure library loading in Samba
- SUSE Linux update for samba
- SUSE Linux update for samba
- Ubuntu update for Samba
- Red Hat update for Samba
- Ubuntu update for Samba
- openSUSE update for Samba
- CentOS 7 update for Samba
- CentOS 6 update for Samba
- openSUSE update for Samba
- Arch Linux update for Samba
- Amazon Linux AMI update for samba
- Multiple vulnerabilities in Western Digital My Cloud
- Samba vulnerability in D-Link DNS-320L/LW
- openSUSE update for samba
- SUSE Linux update for samba
- SUSE Linux update for samba
- Multiple vulnerabilities in Schneider U.motion Builder
- Gentoo update for Samba
- Insecure library loading in samba (Alpine package)
- Fedora 25 update for samba
- Fedora 24 update for samba
- Fedora 26 update for samba